Social media platform X is investigating a wave of account takeover attempts following the wider rollout of its X Money payment service. Several users reported receiving password reset emails despite never requesting them.
X Product Engineer Mridul Singhai said the company was aware of the activity and was investigating the matter. So far, X said it had found no evidence that the attacks had resulted in a widespread account breach.
Singhai explained that the attackers were suspected of attempting to exploit the launch of X Money to gain unauthorized access to user accounts. According to him, X’s team is still tracing the source and patterns of the attacks that triggered the large number of password reset notifications.
X has also asked users to remain patient while the investigation continues. The company acknowledged that the large volume of emails received by users could cause concern, particularly as the new payment service has begun expanding its availability.
X Money is a payment service developed by X to expand transaction capabilities within the platform. The service includes integration with bank cards and other payment benefits, including helping creators receive payments from their activities on the platform.
The introduction of financial features could increase the value of X accounts to cybercriminals. If certain accounts are connected to payment services or digital economic activities, unauthorized access could provide opportunities for further misuse.
X General Counsel James Burnham also condemned the attacks targeting users. He said the company’s security and legal teams would work to identify the perpetrators and pursue legal action against them.
While the investigation continues, reports of password reset emails are still emerging among users. The situation has prompted X users to strengthen the security of their individual accounts.
One widely recommended measure is enabling two-factor authentication. The feature provides an additional layer of security, meaning account access does not rely solely on a password.
Grok, the chatbot developed by X, has also responded to several user questions regarding the suspicious activity. Grok confirmed that attack attempts had occurred but said there was no indication of a successful mass hacking campaign.
Users are also being encouraged to take advantage of the security features available on X. This is particularly important for accounts connected to financial services, as the risk of misuse could increase as more transactions take place within the platform.
Fajar Santoso is a lifestyle and travel writer at RakyatPost who focuses on culture, tourism, modern living, and destination storytelling across Asia and beyond. With a passion for discovering unique experiences and local traditions, he creates engaging content that inspires readers to explore new places, lifestyles, and perspectives. His writing blends informative journalism with creative storytelling to deliver meaningful and reader-friendly travel and lifestyle coverage.
